Jump to content

AlanD

Members
  • Posts

    1,102
  • Joined

  • Last visited

Everything posted by AlanD

  1. Normally - Hard Disk Temperatures normally seem warm...but when a disk has failed - I have noticed that all the disks often seem hot. I am beginning to suspect that when there is a disk error - the raid controller/disk drive strive for a while to recover/re-read sectors from across the stripe...eventually this sector is marked as bad of course - and often there are a cluster of sectors that get remapped at once. I have wondered if this atypical activity on the RAID controller affects timings and triggers (possibly a false) alert than sectors are failing on another drive or two. It just seems "spooky" to me that several disk seem to fail in a relatively short period...and I have seen this a number of times....but perhaps its a power glitch....or something (although we use a UPS).
  2. Don't think you need to spend £1000 when windows server backup works just fine .... although I admit we use Backup Exec ...which is a bit dated...but I quite like hanging on to tapes for a few months just in case we need to go back in time for something.
  3. Well... you'll need some software capable of reading and writing - to what is essentially a sequential storage medium. Usually they have a SCSI interface - so you should see something in the device manager under SCSI. As for software - Symantec's Backup Exec can use tapes....including AIT....Not sure if there is anything you can use for free which uses tapes though... AIT was always a nightmare as far as I was concerned. Not sure if I was unlucky - but we used to eat our way through their tape libraries with sony sending us replacement ones from some European distribution centre on next day delivery. Must have cost them a fortune.....Don't think I ever had to recover something in anger - which is just as well because I wouldn't have been very confident of getting the data back. Fortunately our D2D2T seemed to have a reliable set of disks....and we always ran them as a RAID 5 despite this making backups take a bit longer. Was very happy after moving to LTO.
  4. Sorry - it may be pedantic - but free is free, and its clearly not free (I couldn't have it for nothing, for example) - but it is "included". I agree its not costing you extra - so its a free add on - yes. But its not free.
  5. Another Eclipse (.net version) user here. Can't understand why they are charging so much for hosted version - so we run it on our MIS box. I agree with some earlier comments that INTAKE is always a nightmare... student who change names, leave, then return, being careful not to delete users who leave but might still be chased for overdue books. Would be good if all data came from AD and MIS and library systems added their data to that....with school admin staff responsible for creating and updating AD entries.
  6. ...and smoothwall...or pfsense if you want to do it for free. As always - my advice is get some in and test them. Only you can make the right choice. Knowing that 90% of schools have a product doesn't necessarily make it the right product for your school. Meeting the requirements of the "prevent" strategy" should be high on your "wanted" list. The prevent strategy requires you to "monitor" use (not necessarily block) of a number of categories with lists supplied by government. Some web "filters" made outside the UK rarely meet this requirement....or at least not without considerable user configuration.
  7. ...to be honest ...this doesn't sound like an RM issue....so its not going to go away by moving to vanilla....
  8. Is it worth running a check disk (with the "fix" flag) ... and possibly doing it safe mode....then reboot and try again?
  9. Not sure what you mean by hyper V host? Do you mean just the host? Why would you do that when it's so easy just to reinstall? So I'm guessing you want to back the virtual machines. Many backup applications are VM aware and will backup all the virtual servers..but are not free, nor, depending on you budget cheap. I've always thought windows backup was pretty good and deserves a better press. It's certainly good value for money. You could get two physical hosts to backup to each other, or use a rotation of large capacity usb3 sata Drive, if you want to avoid the cost of dedicated backup server. Keep in mind that current malware, ransom ware in particular is backup aware, and often delete or cripples any backups it can find, including cloud backups if they are connected....in fact they do their best to cripple them before encrypting files, so by the time you realise there is an infection the backups have gone. This might persuade you to use off line tapes. Certainly you need to disconnect backup media..online included. Be sure to understand the data on your servers. Most of us know that sql and exchange databases need special support.But you can get caught out if some external contractor installs administration or accounting software that uses some other database not supported by your software. Usually all these have their own way to back up databases and you need to use those facilities. Simply having a copy of your data using veeam or backup exec will not enable you to recover the database. Those databases need backing up with their own tools. In fact sql has its own backup tools so you can use those rather than pay for an extra option...which often actually uses that backup facility itself.
  10. If you are just looking to use RMUnify for Office 365 and Google sync - there is no value in it - because there are free and easy to use (Microsoft and Google) tools to do this - and they sync groups, users and passwords just fine. So any value will need to be in what else it delivers. Syncing with an MIS is useful - that's certainly worth something. And yes - there are single sign on capabilities for a number of applications (although - often not the good ones you would like to use). There are alternatives - Magellan - for example has improved enormously - and does logons for sites that do not support federated SSO. It also provides external access to domain stored data which from RM would be the cost of another product - Portico. And Magellan in cheaper..... As in all cases - its important to get a test installation and evaluate these products. Don't take anyone else's word for how great something is....not least of all because they all have some short comings and irritations.
  11. I am going to weigh in here - and reiterate my beliefs - which is: You need to get some kit in and test it. I'm not saying that "sellers" will sell you something inappropriate - but you need to be in an informed position to negotiate. Yes - Ubiquiti is "cheap" - but don't let the price put you off, or let the ignorant rubbish it. It clearly works well in lots of schools - and has no on going licence costs and is fully functional with VLANs, RADIUS, AD, load balancing, band steering, airtime fairness and all the rest of it. But don't take my word that it would do the job either. Be clear about what you want to achieve. There are multitudes of myths and false beliefs and expectations - and sometimes downright lies surrounding what wireless can do. Don't get blinded by multigigabit connection speeds quoted in the literature. You are not going to achieve those - even with the latest most expensive kit. 11Mb/s "b" connections produced real world data rates of 2 to 3Mb/s. Fine for a single PC webbrowsing - but useless for a class. With 13 channels you could, however, use multiple APs easily. 54Mb/s "a/g" connections will deliver somewhere between 20 and 30Mb/s of real data - but use 20Mz channels - rather inefficiently and you could usually manage to use channels 1,4,9,and 13. (Remember that wireless is a half duplex medium, and has no means to avoid packet collisions other than random back off times) 150Mb/s "n" connections were an ingenious result of applying mathematics to the problems of wireless transport and allowing the use of wider 40MHz channels - and more than doubles the real data rate to around 80 or 90Mb/s. One slight downside is that because it makes really good use of the frequency channels you can now only use channels 1 , 6 and 11 on the 2.4GHz band. (There might be some merit in using 1, 7 and 13 - but not all wireless clients like anything above channel 11 - because 12 and 13 are not used outside the USA). "n" technology was the first that allowed us to get anywhere near using laptops in classrooms. But its far from ideal. Sharing even a 100Mb/s between 30 laptops doing a domain login and loading a user profile can be painfully slow. In fact real world data rates suffer quite a lot when you have 30 clients hitting the airways at once because collisions become increasingly detrimental. (I'll mention here that MERU has a technology that minimizes this degradation ...although while it offered advantages with densely packed classrooms using 2.4Ghz - I couldn't see it made much difference with today's wireless standards). After that you can add two or three streams - assuming that your client supports them. Don't go all starry eyed and believe that this is going to give you a data rate of 300 or 450Mb/s. Its only going to be a theoretical bit rate connection. It relies on spatial separation - and gain in real world data rates is only going to be around 20% at best. So now we are up to 110Mb/s - maybe 120Mb/s. A gain worth having - but its not transformational. The we had "ac1" (first wave of "ac"). While this has beamforming and higher QAM, its main potential advantage is wider channels of 80Mhz (or possibly 160Mhz). The trouble is that its almost impossible to deploy these wide channels sensibly in classroom blocks as there are relatively few 80Mhz channels. Turning the power right down (remember to do this on clients as well as access points) can help - and yes, access points and clients will to some extent attempt to arbitrate channels and widths in an attempt to optimise their capacity....but if you have heavy use in all these classrooms you might well find you are best sticking with 40MHz channels. The result is that real world data rates are still under 150Mb/s. Worse still, is that the fact that most ac1 clients are single stream only - partly because it saves on battery charge. So expect to lose 20% - which might be all the gain you achieved in moving from "n" to "ac1". Don't misunderstand me here: for a smaller number of connecting clients and using wider channels you will get data rates of up to 300Mb/s - but not where you need them most - in a cluster of heavily used classrooms. "ac2" has up to 8 streams - and adding streams obeys laws of diminishing returns so another 20% at best - but only in a world that doesn't exist because there are no 8 stream clients. It also offers MU-MIMO. This is a real progress. But don't get taken in by pictures showing you 4 clients each being served by a single stream. Just like any spatial stream system - you need to remember the waves of the streams are on the same frequency - and much of the potential gains are lost. However - you will get around a 20% overall increase in data rates - and that's worth something. There are schools that have taken out fixed ICT suites and use classrooms of laptops instead. They are on a steep learning curve. Yes - you "can" get high wireless speeds, and there are some gains to be had with latest "ac2" technology....but its not transformational but I think you need to think twice before throwing money at equipment believing it will solve the problems of wireless. You might well find that better positioning of access points (typically 1 per classroom - but it depends on your walls), perhaps replacing the wireless cards in your client devices, etc will bring you equal if not better benefits for your users.
  12. This may not be helpful ...but I wouldn't be doing it this way. Exporting and importing user details - YUK! I would use smoothwall's radius server - and get smoothwall to authenticate against your AD. Then I would configure Aerohive to use smoothwall's radius for authentication - rather than Aerohive's PPSK system (which I assume you are using)....or at least I would do that for BYOD. For school devices (but not domain PCs) I would use smoothwall's captive portal (again using its integration with AD) with a timeout equal to the length of a teaching period. FOR domain PC's - yes I'd probably use smoothwall as a proxy. I would segregate the various traffic from domain/BYOD/staff/etc onto different VLANs and different physical networks on smoothwall - and add rules to allow any necessary communication - such as allowing mobile devices access to print servers, or staff devices access to airservers. Setting this up - is clearly not trivial...and you will need to think about DNS as internal addresses will need to resolve correctly etc. Can't help thinking that you need Aerohive installer and Smoothwall installer - to spend a day together to make it work.
  13. I think configurator 2 - even in its latest incarnation - is one of the buggiest pieces of software I've used. If you start from a completely blank set of ipads - fine - but if you have a random selection with different versions of different apps installed - and you need to update them...well welcome to world of chaos - not to mention crashes and error messages. You will soon decide its worth using an MDM for subsequent maintenance - even if you have to pay it.
  14. For a small setup.80 pcs...I'm guessing midline sata drives will be fine.... unless you start doing video editing....and if you use server 2016 ... I think you can assign an SSD as cache...but I might have dreamt that...
  15. We have an RM server running printer credits and is the printer server for our network. Our problem was increasingly degradation of response time, eventually leading to inability to login....but we have what looks like a memory leak. RM couldn't fix it (sometimes wonder what we pay for...but to be fair they did spend a fair bit of time on it...) so we whacked 32Gb ram in and it settles down to using around 16Gb. Is your memory use static ...less than 8Gb? Set alarm bells ringing because we have a lot ok Konica Minolta printers too....we experimented with different versions of drivers...but couldn't prove this as a cause...and the trouble is we didn't have the luxury of experimenting on a production server box...
  16. Does RM support not "fix" this for you? Its not AV getting in the way is it? It installed OK for us on a 2008R2 server. (My niggle with Portico- is that when using an iPad - it insists on opening a word document straight away in pages...even though you have Office 365 and a word app)
  17. If you mean "no authentication" - when you say "open proxy" - then that presumably means you have no way to monitor who goes to what web site. That would - in my understanding - not meet the requirements of the prevent strategy - where "monitoring" by user is probably more important than filtering - if we are to track violence/hate/selfharm/radicalisation etc. If you were to run the iPads on a separate (wireless) VLAN - which I assume you are not doing - then you could make he gateway address be lightspeed. It would then not be necessary to use a proxy...and you could use a captive portal to authenticate. It sounds as if lightspeed is as useless as smoothwall when it comes to mobile devices - because inspecting authenticated https traffic breaks lots of standard stuff....and by the time you rewrite all the necessary rules and exceptions you wonder what you were paying for. ...but smoothwall is quite good at reporting for "prevent" - but only quite good - because you don't get the ability to tailor those reports as you can with normal reports. ...I'm pretty certain there would be no way to do off-site filtering without a proxy - unless there is some kind of "app" or bespoke web browser in the device.
  18. I'm not going to defend "defender"...nor for that matter any other antivirus/malware product.....but... Keep in mind that no protection software is going to give you 100% protection. I few years ago I remember Norton or some such product being tested and was found to be effective against 60% (yes...only 60%) of current malware at the time. ...and that was one of the better products tested. And while some products claim to offer some protection against zero day attack there is no guarantee its going to protect you against the attack you might experience. Simply paying money for a separate commercial product may give you a sense of peace of mind - but to be honest it would be largely an illusion - although its one I have been happy to invest in - if only to be able to say to SLT - that yes we pay for a product to protect us. But if you are really thinking "FEP/Defender is useless and is going asap" don't imagine for a monent that other products are going to be better. Hopefully - you have analysed carefully how the attack managed to compromise your network....I'm thinking it must have been a user with elevated or administrator priviledges - or perhaps you have no restrictions on what executables your users can run. "Drive by" infections are an increasing menace...and malicious email attachment attacks increasingly sophisticated as attackers now seem to to harvest first/last name and company names etc which make such emails seem genuine.
  19. Hang on a minute....no one is asking for wat is "best". ... what is required is something that is suitable for the job...which in this case is 80 users. And even an old hobbled RM server...would manage that job...just fine. Whether you need two boxes...or virtual servers depends to some extent how critical the role is. Yes, being without a computer system for a couple of days is often inconvenient...but rarely business critical...especially if email is hosted externally...even user files hosted externally. ..then even less so.
  20. Simple passwords for public services are not a good idea.
  21. Well - I think ceiling mounts make more of a difference than a simple test might indicate. Ideally - with lots of access points and clusters of classrooms you need the power of the Access points to be really low....especially if you want to use the wide channels that new APs can provide. I found it help turning the transmit power down in the laptops themselves too - as that gave far less contention two classrooms away where the same channel was getting reused. We are a secondary school - and placing the (5GHz) client (with low power) at the back behind some burly lad with the access point on the wall at the front halved the data rate. I decided it was silly investing in better access points and clients and lose it all because I couldn't be bothered to reposition the APs. It might be different with little ones in a primary school because they are less likely to obscure the wireless paths. Like most things - just laying out the money and expecting or hoping its all going to work brilliantly like magic is not enough. Planning and testing (always high on my list) will possibly give more improvement than just buying better stuff.
  22. Well...there is other stuff out there...maybe not as good but cheaper and will do the job.......I think the prevent strategy has allowed these suppliers to charge what they like.
  23. I would check that you have access points in the ceiling of every classroom. Sharing access points (often from the corridor) was fine with 2.4G but doesn't work well with 5G radios. Its quite a number of iPads.... I would consider the later "HD" access points from Ubiquiti. More expensive...and currently difficult to source in UK. Even if the fibre is not the latest grade - I am guessing it will work fine at 1Gb/s. If there are 4 fibres (or more) it would be useful to aggregate 2 pairs into the switch at each end. (Switches need to be configured to do this) Most switches will take SFP adaptors (make sure it does) so you won't then require media convertors. Of course if your external internet is only 100Mb/s (or less) there was not much wrong with the 100/10 switches...as I assume most of the ipad traffic will be internet use! Improving switches (and access point) may not help! If its a leased line - investigate whether Virgin' Cable 200 300 Mb/s link (if in cabled area) might not give you higher speed and the savings pay for the investment. Even 2 x FTTC lines into a load balancing router might be better value than a leased line. As an alternative wild card....consider a Draytek router and DrayTek access points (I think it supports up to 20 APs). A filtering licence for Draytek is £40 a year..but you would still need some kind of monitoring on the ipads to meet the prevent strategy. And...its worth considering expectations here. Ipad2 only support 1 wireless stream - at - nominally 150Mb/s. With a 2.4G radio its likely to be half this at best assuming 20Mhz channels. And Real data rates half of that again (...half duplex..contended medium etc). Moving to dual band access points at 40MHz channels will improve this...but you still have perhaps 30 ipads in one room connecting to an AP sharing 100Mb internet. That's - OK - just - for browsing...maybe be not so good for youTube ...and what are the other 70 ipads doing? I think later ipads support 2 streams - like ipad air.....and "ac"? But if you don't have these - you may not see the transformation that might be expected.
  24. Yes...but 3 ...in a same week....after perfect performance for almost two years...I would be thinking maybe a mains electric blip...although the server is fed from a UPS....possibly warmer weather....software update being less tolerant....
  25. We have 8 drives in our D2D2T unit- SATA - 3.5 inch Enterprise - 7.2K with LSI 92608i controller (latest firmware/drivers etc) Originally they were Toshiba 2TB drives and after two years they started to become really problematic - usually the error reading seemed to correct itself - but not before the backup process hiccupped and failed. Tried replacing them under the 3 (or was it 5) year warranty these drives carry - but discovered that because they were sold as part of the appliance they were OEM - and only covered for one year. Running really hot to touch - despite fans drawing air over them. Anyhow - bit the bullet and replaced with 4TB DELL Enterprise disks -(Made by Seagate) supposedly new. All ran nice and cool - and problem free until.... Aain 2 years later - I am back with backups failing and "recovered" sector errors on one drive. Bought a new drive - but before I could replace it a different drive actually failed. Replaced failed drive, rebuilt OK. And ordered another drive and replaced the one originally giving problems...and now...a third drive produced some "recovered" sector errors. And unsurprisingly I now have a bad block - so will need to reformat - or something. Aghh..... Again drives feel hot to touch. Am I just unlucky? Apparently unless the drive actually fails I can't replace it under warranty because some remapping of sectors is expected (frankly I start getting really nervous when this happens ...). And why do all drives run fine for two years and then within the space of a week or so do several start to look as if they are going to fail? In fact the drives have no warranty - as although I bought them new and packaged - they had been sold as OEM drives (how would I have known this?)
×
×
  • Create New...